CVE Tools
Back to feed
Exploited in the wild Identity Services Engine (ISE) zero-day ISE Passive Identity Connector (ISE-PIC) Cisco auth-bypass

Cisco warns of max severity ISE zero-day exploited in attacks

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

Cisco has patched CVE-2026-76460, a maximum-severity authentication bypass affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), which is being exploited in the wild. A crafted request to an affected API can let a remote attacker evade authentication and access the device's web management functions. Organizations should upgrade to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4, as Cisco has not provided a workaround.